Bozdoz develops web-mapping and content-security plugins, with a focus on Leaflet Map and reCAPTCHA integration products that extend functionality in WordPress and similar platforms. The durable signal centers on application-layer web vulnerabilities, particularly cross-site request forgery and cross-site scripting issues inherent to plugin-based extensions that handle user input and form interaction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bozdoz over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39646MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bozdoz Leaflet Map leaflet-map allows Stored XSS.This issue affects Leaflet Ma | Apr 8, 2026 | 6.5 | 24 | NO | NO |
CVE-2024-3940HIGH The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them | May 14, 2024 | 8.8 | 23 | NO | NO |
CVE-2021-24468MEDIUM The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low | Aug 2, 2021 | 5.4 | 19 | NO | NO |
CVE-2023-5050MEDIUM The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.0 due to insufficient input sanitization and | Oct 20, 2023 | 5.4 | 16 | NO | NO |
CVE-2025-32494MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in bozdoz reCAPTCHA Jetpack recaptcha-jetpack allows Cross Site Request Forgery.This issue affects reCAPTCHA Jetpack: from n/a throu | Apr 9, 2025 | 4.3 | 15 | NO | NO |
CVE-2024-3941MEDIUM The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make l | May 14, 2024 | 4.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bozdoz.
Media articles that mention a CVE ID that affects a product developed by Bozdoz — matched by CVE ID, not by vendor name.